CVE-2026-72403

Source
https://cve.org/CVERecord?id=CVE-2026-72403
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72403
Downstream
Published
2026-08-15T05:56:27.464Z
Modified
2026-08-16T03:48:53.760336950Z
Summary
ALSA: FCP: Fix NULL pointer dereference in interface lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: FCP: Fix NULL pointer dereference in interface lookup

A malformed USB device can provide a vendor-specific interface without any endpoint descriptors. fcpfindfc_interface() currently selects the first vendor-specific interface and reads endpoint 0 from it, without checking whether the interface actually has any endpoints.

When bNumEndpoints is zero, no endpoint array is allocated for the parsed alternate setting, so getendpoint(..., 0) yields an invalid endpoint descriptor pointer. Dereferencing it through usbendpoint_num() then triggers a NULL pointer dereference.

Skip vendor-specific interfaces that do not have any endpoints.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72403.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
46757a3e7d50dac923888e7fbe68377736f13c70
Fixed
f28d7b5f1578a7501ab17b10643ed1e4f729187e
Fixed
3ab06151ffcb8c3aeb8f78508658b6c0f05be932
Fixed
e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72403.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72403.json"